Melcoz is a Brazilian banking trojan associated with the Latin American banking-malware cluster known as the Tétrade, alongside Guildma, Javali, and Grandoreiro. It has been linked to campaigns that expanded beyond South America into other regions, including Europe. Melcoz targets Windows systems and is designed to facilitate online banking fraud through credential theft and session manipulation.
Core functionality attributed to Melcoz includes theft of credentials stored in web browsers, monitoring of clipboard contents, and surveillance of victim browser activity during online banking sessions. It can watch for banking activity and display overlay windows to manipulate the user session in the background, a behavior consistent with banking-trojan tradecraft aimed at harvesting sensitive information and enabling fraudulent transactions.
Observed execution and evasion techniques include use of DLL hijacking, VBScript-based execution of malicious DLLs, MSI packages containing embedded VBScript, and distribution through an AutoIt loader. Samples have also been protected with commercial packers such as VMProtect and Themida to hinder analysis and evade detection. Delivery has been observed via malicious links embedded in email messages, consistent with phishing-based infection chains.
Melcoz is part of the broader ecosystem of Brazilian banking malware that increasingly targets financial institutions and banking customers across multiple geographies. Its behavior aligns with financially motivated operations focused on browser-stored credentials, active banking sessions, and user interaction abuse to support account compromise and fraud.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Multiple actors and malware families are described as sending spearphishing/phishing emails containing malicious links (including shortened URLs, cloud-hosted links, and links to archives or documents) to deliver malware, harvest credentials, or redirect victims to malicious content.
APT-C-36 has embedded a VBScript within a malicious Word document which is executed upon the document opening.
APT39 has utilized AutoIt and custom scripts to perform internal reconnaissance. Melcoz has been distributed through an AutoIt loader script.
Denis exploits a security vulnerability to load a fake DLL and execute its code. Empire contains modules that can discover and exploit various DLL hijacking opportunities. PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit DLL hijacking opportunities in services and processes.
"AppleJeus ... has also used DLL search order hijacking via the IKEEXT service, running with LocalSystem privileges, to load the TAXHAUL DLL for persistence." / "APT41 ... has used search order hijacking to execute malicious payloads" / "Cinnamon Tempest has used search order hijacking to launch Cobalt Strike Beacons."
"Sandworm Team used UPX to pack a copy of Mimikatz"; "APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium"; "Lazarus Group packed malicious .db files with Themida to evade detection."
“AppleJeus delivered components using a Windows Installer package (.msi)… executed the 3CXDesktopApp.exe…”, “APT38 has used msiexec.exe to execute malicious files.”, “Rancor has used msiexec to download and execute malicious installer files over HTTP.”, “TA505 has used msiexec to download and execute malicious Windows Installer files.”
Denis exploits a security vulnerability to load a fake DLL and execute its code. Empire contains modules that can discover and exploit various DLL hijacking opportunities. PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit DLL hijacking opportunities in services and processes.
"AppleJeus ... has also used DLL search order hijacking via the IKEEXT service, running with LocalSystem privileges, to load the TAXHAUL DLL for persistence." / "APT41 ... has used search order hijacking to execute malicious payloads" / "Cinnamon Tempest has used search order hijacking to launch Cobalt Strike Beacons."
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
Agent Tesla can steal data from the victim’s clipboard. APT38 used a Trojan called KEYLIME to collect data from the clipboard. APT39 has used tools capable of stealing contents of the clipboard.
Cobalt Strike can perform browser pivoting and inject into a user's browser to inherit cookies, authenticated HTTP sessions, and client SSL certificates. Dridex can perform browser attacks via web injects to steal information such as credentials, certificates, and cookies. Grandoreiro can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields. IcedID has used web injection attacks to redirect victims to spoofed sites designed to harvest banking and other credentials. Melcoz can monitor the victim's browser for online banking sessions and display an overlay window to manipulate the session in the background. QakBot can use advanced web injects to steal web banking credentials. TrickBot uses web injects and browser redirection to trick the user into providing their login credentials on a fake or modified web page. Ursnif has injected HTML codes into banking sites to steal sensitive online banking information.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as another Brazilian banking trojan grouped alongside Ousaban under the 'Tetrade' label.
Brazilian banking trojan mentioned as a peer family within the same Tetrade grouping as Ousaban.
Uses VBS scripts to execute malicious DLLs.
Credential-stealing malware targeting web browsers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.